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The Information Commissioner’s response to the Welsh 
Government’s consultation ‘Respecting others: Inspiring 
rights, respect and equality’ 


Introduction 


The Information Commissioner is pleased to respond to the Welsh Government’s 
consultation containing a draft Anti-Bullying Guidance and Toolkit for schools. 


The Commissioner has responsibility for promoting and enforcing the EU General 
Data Protection Regulation (GDPR), the UK Data Protection Act 2018 (DPA) and 
additional information rights legislation. 


The Commissioner is independent of government and upholds information rights 
in the public interest, promoting openness by public bodies and data privacy for 
individuals. The Commissioner does this by providing guidance to individuals and 
organisations, solving problems where she can, and taking appropriate action 
where the law is broken. 


Comments on your draft 


The Commissioner notes the proposals that schools should collect more data 
about bullying incidents, much of which would be personal data as defined under 
data protection legislation. The Commissioner recommends that schools are 
strongly advised to work with their Data Protection Officer to ensure that that all 
personal data is processed lawfully and with appropriate protection for the 
individual’s rights. 


The Information Commissioner also notes within paragraph 14.4 of the draft 
guidance that it is for individual schools to determine what data and information 
they collect in the context of the specific bullying issues within their school. She 
considers that a Data Protection Impact Assessment (DPIA) will be required by 
each school in determining what data they need to collect to ensure that it is 
proportionate and that any appropriate steps that may be necessary to mitigate 
risks to individual’s rights are taken. Schools should involve their data protection 
officer in making the assessment. Further information on DPIAs, including the 
obligation to consult the Information Commissioner in certain cases, is available 


here. 
We welcome correspondence in Welsh Information Commissioner's Office (Head Office) 
and this will not lead to any delays. Swyddfa’r Comisiynydd Gwybodaeth (Prif Swyddfa) 
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It is also important to note that the school will need to determine an appropriate 
lawful basis from those listed in GDPR Articles 6 and - if the data is special 
category - Article 9 before they begin processing. Special category data includes 
information revealing racial or ethnic origin, political opinions, religious or 
philosophical beliefs, health, sex life or sexual orientation, among other issues 
less likely to be relevant to this consultation. They will also need to ensure that 
they are not collecting more data than they need and have a clear retention 
schedule for the information. Processing of information for anti-bullying measures 
will need to be reflected within each school’s fair processing information. 


In terms of the GDPR right of subject access, it will be important for schools to 
be aware that personal data relating to bullying issues is likely to be disclosed in 
response to a valid Subject Access Request, unless for example to do so would 
put the individual whose data you are processing (data subject) or another 
individual at risk. In addition, whilst this is outside the scope of the 
Commissioner, Welsh Government may wish to clarify to schools whether 
bullying records would form part of the ‘educational record’ as set out in The 
Pupil Information (Wales) Regulations 2011. Whilst not regulated by the 
Commissioner, the Pupil Information Regulations provide a right of access by 
parents to a copy of their child's education record, and bullying information is 
likely to be disclosable unless to do so would put the data subject or another at 
risk. 


The Commissioner would like to take this opportunity to emphasise the 
importance of increasing knowledge and skills for information governance across 
the teaching profession in both primary and secondary schools as she has 
observed from casework and other contact with schools that capacity tends to be 
very limited across the sector. Perhaps unsurprisingly, secondary schools appear 
to have more capacity for information governance than most primaries and as a 
result, this may leave schools - and particularly small schools - at risk of 
breaching the information rights of staff, parents and pupils. By law all schools 
are required to have appointed a Data Protection Officer (DPO) to ensure that the 
school is aware of and able to meet their obligations under GDPR and the DPA. 


OS 4. 


| 


David Teague 
Regional Manager (Wales) 
Information Commissioner’s Office 


14 February 2019 V1.0 final 


